Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations155 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records4 A records, 175 ms lookupPASS
| A | 13.249.74.84, 13.249.74.11, 13.249.74.102, 13.249.74.76 |
| AAAA | — |
| CNAME | — |
| NS | ns-138.awsdns-17.com, ns-1407.awsdns-47.org, ns-2041.awsdns-63.co.uk, ns-566.awsdns-06.net |
| MX | 10 mxb-00752701.gslb.pphosted.com 10 mxa-00752701.gslb.pphosted.com |
| TXT | +m/sUG+hfFjczduxhEb+SGEA05R/86i+e4khd7tpsNUp0h0WGlm+jbfNgL2LqscdlaZstsHiyArIFO8L... 4jv6a2kead62csrme0912g169s 5b2cdtkq9hd6sfo65lqg6hg4ui 5d8c212ba5a24560a98c25bdb28aba0b Dynatrace-site-verification=51603bbc-0b7e-423a-8cad-097b5336f286__9q7pcg5bvneccg... GxgiU4jA=b4b2478bfce14c2ea277e3ff5b5523c8 MS=A5FC6CDCAA712E9B9D88B62E98D486AD5BAF90E9 _globalsign-domain-verification=3F02zYQTk5YHQIxeKqZjXwMxKEfI-5fwW5O4EgeP7i _ndhpfe69haiufqfok8qdxw18npff5l9 adobe-idp-site-verification=bb8f9b85-a232-4ab6-90f0-68e6afaee558 af6vvj6ll613vqam68dc3artgh brevo-code:3ae1a9924073251ebf3f41b167bfba48 brevo-code:ac66dd1af7831ed721663d23f39f90d0 brevo-code:cbf0f089179ff7db72eb2d9ef9c23bcf canva-site-verification=RIOH3Og7BQv5QJsXwpZZ7A cisco-ci-domain-verification=2a384517e2bf085d429932959e6d63cd9717af2d3999ce774d1... cisco-ci-domain-verification=62b9d75c6b5b82b5abddf99c11e23d44f8971eb55fd25aa8fdd... cursor-domain-verification-zbr012=rbdnYHY0jCiX3l9CJrcbwk3Av docker-verification=e1af7c8f-7485-4fab-947c-0304e6e7e3b5 docusign=8dd612fa-056d-4994-a11a-9c54e3313cd5 docusign=b3c37c35-62b6-4836-b1fb-f6e029067e11 dtm-domain-verification=BAWs71QzQzdQ-ygr529eXCia3-k1dbeDxT8OyXaoihk facebook-domain-verification=hwmw1nhl3ukvxp00ddopudc3lrk6uq fastly-domain-delegation-876807-2025127 globalsign-domain-verification=054B388A366B3A12B53DC31F5E9C213D globalsign-domain-verification=3E17ABCE092B4BB040E78222334AA4DB globalsign-domain-verification=414A46BE5F6C1345D969A219A34EBD86 globalsign-domain-verification=5BFFCED7333520134FEDAF31A78CB1B8 globalsign-domain-verification=5fcebada410565002f44bf0bf882f8fd globalsign-domain-verification=EF351B41E2E8802C8D8CA985673A173B globalsign-domain-verification=S6CtPWZkg-5-rT6NTG-hxEUd8UI3YpG2jyHBiCN_LD globalsign-domain-verification=ea2585ec3a1c121b58c60aa4def634c1 google-site-verification=-EmUKAv2PNAWuUkZp7wmPDHAtmfYR5k0s9Rl_7ttG7U google-site-verification=49UeUVI_Zxza8ccu1mg8ofmzhV2G0_TzgOBE9sUr7AA google-site-verification=ZDMGruDurbLHjPjkdgsXzWD1LZ6Wb_NszyaIsoywhpM google-site-verification=szo-diBANWjUHa8fEcRcKUZLYA0KKyBGY3DPch2Dzxs heroku-domain-verification=z34orozdt0jybdyg1kqw/hodlyqxdgee624cigtt5be hubspot-60QvfwsUHwVmo ih51a9ch3m7rlcdt3237hh2fa9 imgq4turr20120m92vh05ogpl4 intersight=5701b978feab53d8aaedb4b3edd1303f0aade537955200f2499e29abae5eb4ec jamf-site-verification=RGiXkDrfeXP7MdUgpi7MuQ k933ogci7fkk8sovuplfrhvhgl kp8llcjf0ggjc6ulintg1jp662 mistral-domain-verification=12a09a13d41b5bac563d70e71237b27d87faf8bd ozRmIoUJ2hszXG1Vap5icJuwBrloQ021gvDsfmVXhe8YN1AdDLV9v54mvK0tp0VtOyIvOU+Sm+8AfN95... perplexity-ai-domain-verification-szy3np=oZ9iQmNINYX34U38H18glxxpi pjuu55pfrmb1fddij2b208vpjb slack-domain-verification=0OVGlo474XBSwgIBnapbEyACznS2FPh3JBINHDqO smartsheet-site-validation=vw_QhyPgb8dziL-wK6ZoS-tyf6AInBXx u801dcm0uv4p3ghl5o5knl9a7o uqnh2gngsur8lun735t2h5qerv SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all wrike-verification=NjY2MjI0MTowZjVkYzU5YWU3MGM5YjEyNGNkZmE0YzFmZjhmNzYyZjFkOGFmM... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 475 ms totalPASS
https://3ds.com
197 ms · HTTP/1.1
https://www.3ds.com/
277 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://3ds.com | 301 | 197 ms | HTTP/1.1 | AmazonS3 |
| 2 | https://www.3ds.com/ | 200 | 277 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 4 URLsPASS
User-agent: *
Disallow: */search*
Disallow: /fileadmin/bbc/*.pdf$
Disallow: /fileadmin/cards-static/*.pdf$
Disallow: /fileadmin/COMPANY/*.pdf$
Disallow: /fileadmin/depositary/*.pdf$
Disallow: /fileadmin/EVENTS/*.pdf$
Disallow: /fileadmin/general/*.pdf$
Disallow: /fileadmin/PRODUCTS/*.pdf$
Disallow: /fileadmin/Suppliers/PDF/*.pdf$
Disallow: /fileadmin/Support/*.pdf$
Disallow: /fileadmin/TERMS/*.pdf$
Disallow: /fileadmin/Training/*.pdf$
Disallow: /assets/path/*.pdf$
Disallow: /fileadmin/customer-stories/*.pdf$
Disallow: /fileadmin/industries/*.pdf$
Disallow: /uploads/*.pdf$
Disallow: /common/*.pdf$
Disallow: /Content/*.pdf$
Disallow: *?fbclid
Disallow: *?utm
Disallow: *?openstat
Disallow: *?from
Disallow: *?gclid
Disallow: *?yclid
Disallow: /*.asp
Disallow: /*?height
Disallow: /*?*cHash=
Disallow: /*?*int_campaign=
Disallow: /*?*xtcr=
Disallow: /*?*pageID=
Disallow: /*?*lang=
Disallow: /*?*type=
Disallow: /*?*gad=
Disallow: /*?*id=
Disallow: /*?*code=
Disallow: /*?*linkId=
Disallow: /*?*scid=
Disallow: /*/contents/feed/
Disallow: /*/rss/
Disallow: /*?*source=
Disallow: /*?*RCid=
Disallow: /*/ds-header.min.js
Allow: /*/ds-header.min.js?page=homepage
Sitemap: https://www.3ds.com/sitemap/sitemap.xml
# AI crawlers - allow llms.txt resources
User-agent: GPTBot
User-agent: ChatGPT-User
User-agent: Claude-Web
User-agent: ClaudeBot
User-agent: PerplexityBot
User-agent: Applebot-Extended
User-agent: cohere-ai
User-agent: Bytespider
User-agent: CCBot
User-agent: MistralAI-User
User-agent: Google-Extended
Allow: /llms.txt
Allow: /llms-ctx.txt
Allow: /llms-ctx-full.txt
Allow: /llms-sitemap.txt
Allow: /*.md
# LLMs.txt
Llms-txt: https://www.3ds.com/llms.txt
A+Domain Intelligence3ds.com — via SafeBrands SAS, 31 years, 2 months old, hosted on AWSPASS
1140 days
July 28, 2029
155 days
Issued by Amazon
31 years, 2 months
Registered July 29, 1995
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
13.249.74.84
SafeBrands SAS
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice